About the Role
We are seeking a highly motivated HIPAA & SOC 2 Compliance Specialist to join our Governance, Risk, and Compliance (GRC) team. In this role, you will be responsible for driving and maintaining the organization’s HIPAA compliance program while leading SOC 2 Type II audit readiness and ongoing compliance initiatives.
You will work closely with Engineering, DevOps, Human Resources, Product, and Operations teams to ensure security controls are effectively implemented, monitored, and documented. The ideal candidate will have hands-on experience managing compliance frameworks, coordinating external audits, conducting risk assessments, and ensuring the protection of sensitive healthcare information (PHI).
Key Responsibilities
- Lead and manage the organization’s HIPAA compliance program and SOC 2 Type II audit lifecycle.
- Plan, coordinate, and manage SOC 2 Type II observation periods, audit readiness activities, and annual recertification efforts.
- Collect, review, and maintain audit evidence to demonstrate the effectiveness of security and operational controls.
- Develop, maintain, and improve security policies, procedures, and compliance documentation.
- Perform periodic risk assessments and identify compliance gaps across infrastructure, applications, and business processes.
- Collaborate with Engineering, DevOps, HR, and Operations teams to implement corrective actions and strengthen security controls.
- Ensure appropriate safeguards are in place for Protected Health Information (PHI) in accordance with HIPAA Privacy and Security Rules.
- Monitor compliance with access management, identity management, data retention, encryption, vulnerability management, and incident response policies.
- Coordinate internal compliance reviews and support external auditors throughout audit engagements.
- Track remediation activities and ensure timely closure of audit findings and compliance issues.
- Provide compliance awareness and security best practice guidance across the organization.
- Stay current with evolving regulatory requirements, industry standards, and emerging security risks.
Job Requirements
- 3-5 years of experience in Information Security, Governance, Risk & Compliance (GRC), IT Audit, or Compliance roles.
- Strong hands-on experience managing HIPAA compliance programs and SOC 2 Type II audits.
- Thorough understanding of HIPAA Privacy Rule, Security Rule, and Protected Health Information (PHI) requirements.
- Strong knowledge of SOC 2 Trust Services Criteria, including Security, Availability, Confidentiality, Processing Integrity, and Privacy.
- Experience performing security control assessments, risk assessments, and compliance gap analyses.
- Experience collecting, organizing, and maintaining audit evidence and compliance documentation.
- Familiarity with security controls such as Identity and Access Management (IAM), Multi-Factor Authentication (MFA), encryption, logging, vulnerability management, backup, and disaster recovery.
- Strong documentation, analytical, problem-solving, and organizational skills.
- Excellent verbal and written communication skills with the ability to work effectively with auditors and cross-functional teams.
- Bachelor’s degree in Computer Science, Cyber Security, Information Technology, or a related field.
Nice to Have (Added Advantage)
- Professional certifications such as CISA, CISM, CISSP, CRISC, HCISPP, or ISO 27001 Lead Implementer/Auditor.
- Experience with additional compliance frameworks such as HITRUST, ISO 27001, NIST CSF, GDPR, or PCI DSS.
- Experience working in cloud environments such as AWS, Microsoft Azure, or Google Cloud Platform (GCP).
- Familiarity with compliance automation and GRC platforms such as Vanta, Drata, Secureframe, Sprinto, or similar tools.
- Experience supporting healthcare technology, SaaS, or cloud-native platforms.
What You’ll Work On
- Leading HIPAA compliance initiatives across the organization.
- Managing SOC 2 Type II audit readiness, evidence collection, and annual certification activities.
- Protecting sensitive healthcare data through effective security governance.
- Partnering with cross-functional teams to strengthen security controls and reduce organizational risk.
- Driving continuous improvement of compliance processes, policies, and security best practices.